Definition · DNS & Email Spoofing
What is Typosquatting?
Typosquatting is the deliberate registration of domains that closely resemble a legitimate domain — misspellings, adjacent-key typos, missing or doubled letters, or plausible variations. Users who mistype an address, or who fail to spot the difference in a link, land on infrastructure the attacker controls.
Common typosquatting patterns
- Character omission or doubling —
exmple.com,exaample.com - Adjacent-key typos —
ecample.com - Character swaps —
examlpe.com - Different TLDs —
example.co,example.netwhen the brand uses.com - Added words or hyphens —
example-login.com,examplesupport.com - Visually similar characters — covered separately as homoglyph attacks
How typosquatted domains are abused
Beyond capturing stray traffic, lookalike domains are the raw material of phishing: they host credential-harvesting pages styled after the real brand and provide believable sender addresses for email attacks against staff, customers, and suppliers. Because the attacker owns the domain outright, they can configure valid SPF, DKIM, and DMARC for it — authentication proves the mail came from the lookalike domain, not that the domain is honest.
Defences
Organisations defensively register the most obvious variants, monitor new domain registrations and Certificate Transparency logs for lookalikes, and pursue takedowns through registrars or UDRP proceedings when abusive domains appear. Training users to check domains carefully helps, but detection and takedown remove the threat at source.